Data Privacy
Data privacy concerns how handling information affects people. It includes collection, use, sharing, access, and persistence. Security controls can support privacy, but privacy problems can occur without an intrusion.
A permitted user can still use too much data
A delivery service needs an address. A regional report may need only a region, and an order-status assistant may need neither. Copying the full address into both systems can create unnecessary exposure even if every account is authenticated.
Identify the purpose, required information, recipients, and retention rules before building the path. A new use needs assessment rather than automatic inheritance of the original purpose.
Follow the effect on the person
A disclosure can cause embarrassment, exclusion, or other harm; organizational inconvenience is not the only concern. Explain actual handling and provide the applicable request process. Privacy is not established merely by displaying a notice or collecting a checkbox. The relevant rules and responsibilities must be implemented and checked.
Reference: NIST Privacy Framework.
Discover more from Insightful Data Lab
Subscribe to get the latest posts sent to your email.
